Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2023-24553HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-29053HIGHA vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The affected applicationEPSS 0.2%CVE-2026-43753MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, maEPSS 0.2%CVE-2026-3285MEDIUMberry-lang berry be_lexer.c scan_string out-of-boundsEPSS 0.2%CVE-2017-13320MEDIUMIn impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with EPSS 0.2%CVE-2023-24552HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2026-22695MEDIUMLIBPNG has a heap buffer over-read in png_image_read_direct_scaled (regression from CVE-2025-65018 fix)EPSS 0.2%CVE-2025-54269MEDIUMAnimate | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-24554HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-24556HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-24558HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-24555HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2023-33123HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2021-29551LOWOOB read in `MatrixTriangularSolve`EPSS 0.2%CVE-2025-54239MEDIUMAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-30796HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contaiEPSS 0.2%CVE-2023-24557HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2025-54240MEDIUMAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-45078MEDIUMA memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges toEPSS 0.2%CVE-2023-45075MEDIUMA memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to writeEPSS 0.2%